Install and Administer Active Directory Flashcards

1
Q

What does the term “Same Sign-On” mean with respect to the Windows Azure Active Directory Sync Tool?

A

Users that have their passwords synchronized to Windows Azure AD will be able to use the same username and password to log into their Azure AD services as well as their on-premises resources.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Why does Microsoft recommend that you create a new Group Policy Object (GPO) for AppLocker in environments where both Software Restriction Policies and AppLocker are in place?

A

If you upgrade a computer that uses Software Restriction Policies to Windows Server 2012 R2 or Windows 8.1, and then implement AppLocker rules, only the AppLocker rules will be enforced.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Which PowerShell cmdlet modifies properties of OU?

A

Set-ADOrganizationalUnit

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Which type of Windows servers responds to forest-wide Lightweight Directory Access Protocol (LDAP) queries over port 3268?

A

the global catalog server

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What comprises the membership list of a local group?

A
  • Users and computers from any trusted domain
  • Global groups from any trusted domain
  • Universal groups from any trusted domain
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What must an Enterprise Administrator do in Active Directory Users and Computers before moving a newly created child OU to a different parent OU?

A

On the properties of the child OU, under the Object tab, clear the Protect object from accidental deletion checkbox.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Which user right gives a user permissions to change the time and date on the internal clock of the computer?

A

the Change the system time local policy

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What comprises the membership list of a global group?

A
  • Users and computers from the same domain as the global group
  • Global groups from the same domain
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Which PowerShell cmdlet deletes user accounts?

A

Remove-ADUser

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

When creating a template user account, why should you set the Account is Disabled property on the account?

A

So no one can use it to log in.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Which edition of a Windows Server 2012 based operating system should be the source of the media that you use to create additional domain controllers running Windows Server 2012 R2 Datacenter edition with the install from media (IFM) method?

A

Windows Server 2012 R2 Datacenter edition

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

How would you grant a group of users the authority to reset user’s passwords for the OUs located in the domain?

A

On the OU, use the Delegation of Control Wizard to delegate the Reset user passwords and force password change at next logon task to the group.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Which command can be used to join a computer to a domain without contacting a domain controller?

A

djoin.exe

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Which operations master role is responsible for assigning Security Identifiers (SIDs) to objects such as users and groups?

A

RID Master

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Which operations master role is responsible for updating references from local objects to objects in other domains?

A

infrastructure master

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

To create installation media for a full (writable) domain controller, what command must you run on a writable domain controller that is running Windows Server 2012 R2?

A

the ntdsutil ifm command

17
Q

In Active Directory Users and Computers, how do you display the Security and Object tab in the properties of an OU?

A

You need to click View and then Advanced Features in Active Directory Users and Computers before clicking on the properties of the OU

18
Q

Which utility synchronizes user passwords from your on-premises Active Directory to Azure Active Directory, letting users access Microsoft Cloud Services with the same password that they use to access on-premises resources?

A

Windows Azure Active Directory Sync Tool

19
Q

Which user right allows a user to add workstations to the domain?

A

the Add workstations to domain local policy

20
Q

Which type of domain controller contains a partial, read-only replica of every domain in the forest other than its own domain?

A

global catalog server

21
Q

Which command can be used to redirect newly created computer accounts from the default container named CN=Computers to a specified container?

A

the redircmp command

22
Q

How many domain controllers can have the domain naming master role?

A

only one domain controller per forest

23
Q

How many domain controllers can have the schema master role?

A

only one domain controller per forest

24
Q

What type of group can include users from any domain within a forest, and can be assigned permissions for in any domain in the forest?

A

A universal group

25
Q

What feature in a Group Policy policies allow you to control the membership of sensitive groups through Active Directory rather than through traditional group membership editing tools, such as Active Directory Users and Computers or PowerShell?

A

Restricted Groups

26
Q

What is the difference between “Same Sign-On” and “Single Sign-On”?

A

“Single Sign-On” is used with ADFS and allows user to access resources without being prompted for credentials if they are logged in to the AD network.. “Same Sign-On” prompts users for credentials even if they are logged in to the AD network.

27
Q

Why can you not use distribution groups to assign permissions explicitly or implicitly through membership in other groups for resources?

A

Unlike security groups, distribution groups are not security principals

28
Q

What type of AppLocker rule would you use to control an application from the Windows store?

A

a packaged app rule

29
Q

How many domain controllers can have the PDC emulator role?

A

only one domain controller per domain

30
Q

Which installation method can reduce the replication traffic that is initiated during the installation of an additional domain controller in an Active Directory domain?

A

the install from media (IFM) method

31
Q

Which user right gives a user permissions to back up files and folders on a computer, but not restore them?

A

the Back up files and directories local policy

32
Q

Which file on a domain controller contains all resource records for the Active Directory domain controller, including its SRV records?

A

Netlogon.dns in the %systemroot%\System32\Config folder

33
Q

How can you ensure that Alice and John are members of the Backup Operators group on every computer in domain?

A

Configure Backup Operators as a restricted group in a GPO at the domain level with Alice and John as members

34
Q

Which service should you restart to re-register all SRV records for a domain controller?

A

the NetLogon service

35
Q

Which user feature protects the computer from the unauthorized installation of any software?

A

User Account Control (UAC)

36
Q

Which command can be used to redirect newly created users from the default container named CN=Users to a specified container?

A

the redirusr command